Skip to content
Open access

Hierarchical Adversarially-Driven Escalation System (HADES) for Network Intrusion Detection

2026 · Computer Modeling in Engineering & Sciences · 0 citations · 44 references

TL;DR

The Hierarchical Adversarially-Driven Escalation System (hades) is introduced, a framework that addresses this vulnerability to adversarial examples through three coordinated mechanisms and maintains near-perfect detection accuracy under both normal and adversarial conditions.

Abstract

: Machine learning has radically transformed network security, enabling intrusion detection systems capable of identifying malicious traffic with near-perfect accuracy on standard benchmarks. However, these systems remain critically vulnerable to adversarial examples—subtly manipulated inputs designed to escape detection—where performance can severely drop under minimal perturbation. This paper introduces the Hierarchical Adversarially-Driven Escalation System (hades), a framework that addresses this vulnerability through three coordinated mechanisms. First, dedicated detectors are trained for each network protocol, enabling each model to specialize in specific traffic patterns it will face in practice. Second, these detectors are continuously hardened by simulating an arms race between an attacking agent, which learns to find the most damaging evasion strategies, and a defending model that adapts in response, thus producing classifiers that remain robust across a wide range of attack types. Third, incoming traffic is routed through a cost-aware pipeline that reserves expensive analysis for uncertain or suspicious flows, keeping average processing time at 5.4 ms per batch on normal traffic. hades is evaluated on CIC-IDS-2018, a large-scale real-world network dataset, and maintains near-perfect detection accuracy under both normal and adversarial conditions, with robustness verified across nine distinct attack strategies and 95% bootstrap confidence intervals of maximum width 0.0007.

Read PDF

Similar papers

Review Open access 2026

Adversarial Evasion in Machine-Learning-Based Network Intrusion Detection: A Systematic Review, Threat Modeling, and Research Roadmap

A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...

Huda Ali Alatawi · 0 citations
Open access 2026

A Sensitivity-Driven Gradient Framework for Adversarial Sample Generation in Deep Learning-Based Network Intrusion Detection Systems

A sensitivity-driven adversarial generation framework (AGF) that identifies and perturbs the most influential traffic features that affect the classifier’s decision boundary to generate statistically consistent adversarial samples with constrained perturbation magnitude is proposed.

Omar Abboosh Hussein Gwassi, O. N. Uçan · 0 citations
Preprint Sep 2026

Robustness Evaluation and Detection of Transferable Adversarial Attacks in ML-Based NIDS

Machine learning-based network intrusion detection systems (ML-based NIDS) are vulnerable to adversarial evasion, where malicious samples are perturbed to evade detection and be misclassified as benign. Despite growing research on adversarial attacks and defenses for ML-based NIDS, comparative evaluations of multiple a...

Huda Ali Alatawi · 0 citations
Open access Aug 2026

Adversarial Transferability in AI-based Network Intrusion Detection: A Comparative Study of ANN and CNN Models

Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.

Aasim Zafar, Shazra Wali, S. B. U. Haque · 0 citations
Preprint Aug 2026

Adaptive Intrusion Detection System using Transformer-Based Neural Networks and Continual Learning Approach with Adversarial Investigation

This work presents an adaptive IDS framework coupling a tabular transformer encoder with a class balanced experience replay buffer that replays benign traffic at every update to stabilize decision boundaries, and investigates the buffer with overt label flipping and stealthy backdoor poisoning attacks.

Azizi Ariffin, A. Haris, F. Zaki et al. · 0 citations
Open access

From threat intelligence to decision theory

A Network Intrusion Detection System (NIDS) watches network traffic and decides whether what it sees is ordinary activity or an attack. Modern systems learn that decision from labeled examples and routinely report accuracies above 99 percent. That number does not answer the question a defender actually faces, which is...

Mayank Raj · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.